Vulnerability index

Browse CVEs

732 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Signature VerificationCWE-347 × clear
CRITICAL 9.1 CVE-2026-4600 Versions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameter valid… Jsrsasign 11.1.1+ Fix from $2,3002026-03-23 HIGH 8.1 CVE-2026-4478 A vulnerability was identified in Yi Technology YI Home Camera 2 2.1.1_20171024151200. This impacts an unknown function of the file home/web/ipc of t… Mitigation only Fix from $1,9502026-03-20 CRITICAL 9.0 CVE-2026-3564 A condition in the ScreenConnect server component may allow an actor with access to server-level cryptographic material used for authentication to ob… Mitigation only Fix from $2,3002026-03-17 HIGH 7.5 CVE-2026-4258 Versions of the package sjcl before 1.0.9 are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation… Stanford Javascript Crypto Library after 1.0.8 Fix from $1,9502026-03-17 CRITICAL 9.1 CVE-2026-27962 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's … Authlib 1.6.9+ Fix from $2,3002026-03-16 HIGH 8.8 CVE-2026-3562 Philips Hue Bridge hk_hap Ed25519 Signature Verification Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to… Hue Bridge V2 Firmware 1975170000+ Fix from $1,9502026-03-16 HIGH 7.5 CVE-2026-32614 Go ShangMi (Commercial Cryptography) Library (GMSM) is a cryptographic library that covers the Chinese commercial cryptographic public algorithms SM2… No fix yet Fix from $1,9502026-03-16 MEDIUM 5.5 CVE-2026-21002 Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application. Galaxy Store 4.6.03.8+ Fix from $1,6002026-03-16 CRITICAL 9.8 CVE-2026-20997 Improper verification of cryptographic signature in Smart Switch prior to version 3.7.69.15 allows remote attackers to potentially bypass authenticat… Smart Switch 3.7.69.15+ Fix from $2,3002026-03-16 CRITICAL 9.8 CVE-2025-52648 HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tamp… Aion 2.1.2+ Fix from $2,3002026-03-16 HIGH 7.5 CVE-2026-32597 PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515… Pyjwt 2.12.0+ Fix from $1,9502026-03-13 HIGH 7.5 CVE-2026-28432 Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP … Misskey 2026.3.1+ Fix from $1,9502026-03-10 HIGH 7.2 CVE-2025-41767 A high-privileged remote attacker can fully compromise the device by abusing an update signature bypass vulnerability in the wwwupdate.cgi method in … Universal Bacnet Router Firmware 6.0.1.0+ Fix from $1,9502026-03-09 CRITICAL 9.8 CVE-2026-28802 Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passi… Authlib 1.6.7+ Fix from $2,3002026-03-06 CRITICAL 9.1 CVE-2026-29000EPSS 6% pac4j-jwt versions prior to 4.5.9, 5.7.9, and 6.3.3 contain an authentication bypass vulnerability in JwtAuthenticator when processing encrypted JWTs… Mitigation only Fix from $2,3002026-03-04 MEDIUM 5.3 CVE-2026-2746 SEPPmail Secure Email Gateway before version 15.0.1 does not properly communicate PGP signature verification results, leaving users unable to detect … Seppmail 15.0.1+ Fix from $1,6002026-03-04 MEDIUM 5.3 CVE-2026-27445 SEPPmail Secure Email Gateway before version 15.0.1 does not properly verify that a PGP signature was generated by the expected key, allowing signatu… Seppmail 15.0.1+ Fix from $1,6002026-03-04 MEDIUM 5.9 CVE-2025-15598 A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.… Sqlbot after 1.5.1 Fix from $1,6002026-03-03 HIGH 7.5 CVE-2026-3338 Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objec… Aws Lc Sys 0.38.0 / 1.69.0+ Fix from $1,9502026-03-02 HIGH 7.5 CVE-2026-22866 Ethereum Name Service (ENS) is a distributed, open, and extensible naming system based on the Ethereum blockchain. In versions 1.6.2 and prior, the `… Ethereum Name Service after 1.6.2 Fix from $1,9502026-02-25 MEDIUM 6.7 CVE-2025-32060 The system suffers from the absence of a kernel module signature verification. If an attacker can execute commands on behalf of root user (due to add… Mitigation only Fix from $1,6002026-02-15 HIGH 8.8 CVE-2026-25922 authentik is an open-source identity provider. Prior to 2025.8.6, 2025.10.4, and 2025.12.4, when using a SAML Source that has the option Verify Asser… Authentik 2025.8.6 / 2025.10.4+ Fix from $1,9502026-02-12 HIGH 8.8 CVE-2026-23687 SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and … Sap Basis Mitigation only Fix from $1,9502026-02-10 HIGH 8.1 CVE-2026-1529 A flaw was found in Keycloak. An attacker can exploit this vulnerability by modifying the organization ID and target email within a legitimate invita… Mitigation only Fix from $1,9502026-02-09 HIGH 8.1 CVE-2026-25793 Nebula is a scalable overlay networking tool. In versions from 1.7.0 to 1.10.2, when using P256 certificates (which is not the default configuration)… Nebula 1.10.3+ Fix from $1,9502026-02-06 CRITICAL 9.6 CVE-2026-1568 Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allo… Mitigation only Fix from $2,3002026-02-03 HIGH 7.5 CVE-2026-0750 Improper Verification of Cryptographic Signature vulnerability in Drupal Drupal Commerce Paybox Commerce Paybox on Drupal 7.X allows Authentication B… Commerce Paybox after 7.x-1.5 Fix from $1,9502026-01-28 MEDIUM 5.3 CVE-2026-24850 The ML-DSA crate is a Rust implementation of the Module-Lattice-Based Digital Signature Standard (ML-DSA). Starting in version 0.0.4 and prior to ver… Patch available Fix from $1,6002026-01-28 MEDIUM 5.5 CVE-2025-15469 Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success … OpenSSL 3.5.5 / 3.6.1+ Fix from $1,6002026-01-27 MEDIUM 5.3 CVE-2026-24807 Improper Verification of Cryptographic Signature vulnerability in liuyueyi quick-media (plugins/svg-plugin/batik-codec-fix/src/main/java/org/apache/b… Patch available Fix from $1,6002026-01-27